Vulnerability Description
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cabextract Project | Cabextract | <= 1.2 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=329891
- http://libmspack.svn.sourceforge.net/viewvc/libmspack/libmspack/trunk/mspack/qtmPatch
- http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=118Patch
- http://marc.info/?l=oss-security&m=128076168623266&w=2
- http://marc.info/?l=oss-security&m=128077976522470&w=2
- http://www.cabextract.org.uk/#changesPatch
- http://www.debian.org/security/2010/dsa-2087
- http://www.securityfocus.com/bid/42173
- http://www.vupen.com/english/advisories/2010/1903PatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/1997Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=620454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60891
- http://bugs.gentoo.org/show_bug.cgi?id=329891
- http://libmspack.svn.sourceforge.net/viewvc/libmspack/libmspack/trunk/mspack/qtmPatch
- http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=118Patch
FAQ
What is CVE-2010-2801?
CVE-2010-2801 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or...
How severe is CVE-2010-2801?
CVE-2010-2801 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2801?
Check the references section above for vendor advisories and patch information. Affected products include: Cabextract Project Cabextract.